Refine your search

2 vulnerabilities found for SIMATIC IPC BX-39A Industrial Edge Device by Siemens

CVE-2025-40805 (GCVE-0-2025-40805)
Vulnerability from cvelistv5
Published
2026-01-13 09:44
Modified
2026-01-13 17:37
CWE
  • CWE-639 - Authorization Bypass Through User-Controlled Key
Summary
Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user.
Impacted products
Vendor Product Version
Siemens Industrial Edge Cloud Device (IECD) Version: 0   < V1.24.2
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.10 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.11 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.12 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.13 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.14 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.15 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.16 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.17 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.18 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.19 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.20 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.21 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.22 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.23 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.24 Version: 0   < V1.24.2
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.25 Version: 0   < V1.25.1
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.5 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.6 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.7 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.8 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.9 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.10 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.11 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.12 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.13 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.14 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.15 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.16 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.17 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.18 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.19 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.20 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.21 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.22 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.23 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.24 Version: 0   < V1.24.2
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.25 Version: 0   < V1.25.1
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.5 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.6 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.7 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.8 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.9 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Own Device (IEOD) Version: 0   < V1.24.2
Create a notification for this product.
   Siemens Industrial Edge Virtual Device (IEVD) Version: 0   < V1.24.2
Create a notification for this product.
   Siemens SCALANCE LPE9413 Version: 0   < V2.2
Create a notification for this product.
   Siemens SCALANCE LPE9433 Version: 0   < V2.2
Create a notification for this product.
   Siemens SIMATIC Automation Workstation 19" Version: 0   < *
Create a notification for this product.
   Siemens SIMATIC Automation Workstation 24" Version: 0   < *
Create a notification for this product.
   Siemens SIMATIC HMI MTP1000 Unified Comfort Panel Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1000 Unified Comfort Panel hygienic Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1000, Unified Comfort Panel neutral Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1200 Comfort Pro for stand (expandable, flange at the bottom) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1200 Comfort Pro for support arm (expandable, round tube) and extension unit Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1200 Comfort Pro for support arm (not extendable, flange on top) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1200 Comfort Pro neutral design for stand (expandable, flange at the bottom) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (expandable, round tube) and extensio Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (not extendable, flange on top) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1200 Unified Comfort Panel Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1200 Unified Comfort Panel hygienic Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1200 Unified Comfort Panel hygienic neutral design Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1200 Unified Comfort Panel neutral design Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1500 Comfort Pro for stand (expandable, flange at the bottom) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1500 Comfort Pro for support arm (expandable, round tube) and extension unit Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1500 Comfort Pro for support arm (not extendable, flange on top) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1500 Comfort Pro neutral design for stand (expandable, flange at the bottom) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (expandable, round tube) and extensio Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (not extendable, flange on top) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1500 Unified Comfort Panel Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1500 Unified Comfort Panel hygienic Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1500 Unified Comfort Panel hygienic neutral design Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1500 Unified Comfort Panel neutral design Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1900 Comfort Pro for stand (expandable, flange at the bottom) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1900 Comfort Pro for support arm (expandable, round tube) and extension unit Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1900 Comfort Pro for support arm (not extendable, flange on top) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1900 Comfort Pro neutral design for stand (expandable, flange at the bottom) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (expandable, round tube) and extensio Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (not extendable, flange on top) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1900 Unified Comfort Panel Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1900 Unified Comfort Panel hygienic Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1900 Unified Comfort Panel hygienic neutral design Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP1900 Unified Comfort Panel neutral design Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP2200 Comfort Pro for stand (expandable, flange at the bottom) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP2200 Comfort Pro for support arm (expandable, round tube) and extension unit Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP2200 Comfort Pro for support arm (not extendable, flange on top) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP2200 Comfort Pro neutral design for stand (expandable, flange at the bottom) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (expandable, round tube) and extensio Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (not extendable, flange on top) Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP2200 Unified Comfort Hygienic Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP2200 Unified Comfort Hygienic neutral design Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP2200 Unified Comfort Panel Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP2200 Unified Comfort Panel neutral design Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP700 Unified Comfort Panel Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC HMI MTP700, Unified Comfort Panel neutral design Version: 0   < V21
Create a notification for this product.
   Siemens SIMATIC IOT2050 Version: 0   < V1.25.1
Create a notification for this product.
   Siemens SIMATIC IPC BX-39A Industrial Edge Device Version: 0   < V3.1
Create a notification for this product.
   Siemens SIMATIC IPC BX-59A Industrial Edge Device Version: 0   < V3.1
Create a notification for this product.
   Siemens SIMATIC IPC127E Industrial Edge Device Version: 0   < V3.1
Create a notification for this product.
   Siemens SIMATIC IPC227E Industrial Edge Device Version: 0   < V3.1
Create a notification for this product.
   Siemens SIMATIC IPC227G Industrial Edge Device Version: 0   < V3.1
Create a notification for this product.
   Siemens SIMATIC IPC427E Industrial Edge Device Version: 0   < V3.1
Create a notification for this product.
   Siemens SIMATIC IPC847E Industrial Edge Device Version: 0   < V3.1
Create a notification for this product.
   Siemens SIPLUS HMI MTP1000 Unified Comfort Version: 0   < V21
Create a notification for this product.
   Siemens SIPLUS HMI MTP1200 Unified Comfort Version: 0   < V21
Create a notification for this product.
   Siemens SIPLUS HMI MTP700 Unified Comfort Version: 0   < V21
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-40805",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-01-13T17:37:11.802050Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-01-13T17:37:40.414Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Cloud Device (IECD)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.24.2",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.10",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.11",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.12",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.13",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.14",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.15",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.16",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.17",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.18",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.19",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.20",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.21",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.22",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.23",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.24",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.24.2",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.25",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.25.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.5",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.6",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.7",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.8",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.9",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.10",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.11",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.12",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.13",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.14",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.15",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.16",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.17",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.18",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.19",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.20",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.21",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.22",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.23",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.24",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.24.2",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.25",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.25.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.5",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.6",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.7",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.8",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.9",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Own Device (IEOD)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.24.2",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Virtual Device (IEVD)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.24.2",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SCALANCE LPE9413",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V2.2",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SCALANCE LPE9433",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V2.2",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC Automation Workstation 19\"",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC Automation Workstation 24\"",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1000 Unified Comfort Panel",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1000 Unified Comfort Panel hygienic",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1000, Unified Comfort Panel neutral",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1200 Comfort Pro for stand (expandable, flange at the bottom)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1200 Comfort Pro for support arm (expandable, round tube) and extension unit",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1200 Comfort Pro for support arm (not extendable, flange on top)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1200 Comfort Pro neutral design for stand (expandable, flange at the bottom)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (expandable, round tube) and extensio",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1200 Comfort Pro neutral design for support arm (not extendable, flange on top)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1200 Unified Comfort Panel",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1200 Unified Comfort Panel hygienic",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1200 Unified Comfort Panel hygienic neutral design",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1200 Unified Comfort Panel neutral design",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1500 Comfort Pro for stand (expandable, flange at the bottom)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1500 Comfort Pro for support arm (expandable, round tube) and extension unit",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1500 Comfort Pro for support arm (not extendable, flange on top)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1500 Comfort Pro neutral design for stand (expandable, flange at the bottom)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (expandable, round tube) and extensio",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1500 Comfort Pro neutral design for support arm (not extendable, flange on top)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1500 Unified Comfort Panel",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1500 Unified Comfort Panel hygienic",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1500 Unified Comfort Panel hygienic neutral design",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1500 Unified Comfort Panel neutral design",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1900 Comfort Pro for stand (expandable, flange at the bottom)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1900 Comfort Pro for support arm (expandable, round tube) and extension unit",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1900 Comfort Pro for support arm (not extendable, flange on top)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1900 Comfort Pro neutral design for stand (expandable, flange at the bottom)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (expandable, round tube) and extensio",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1900 Comfort Pro neutral design for support arm (not extendable, flange on top)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1900 Unified Comfort Panel",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1900 Unified Comfort Panel hygienic",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1900 Unified Comfort Panel hygienic neutral design",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP1900 Unified Comfort Panel neutral design",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP2200 Comfort Pro for stand (expandable, flange at the bottom)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP2200 Comfort Pro for support arm (expandable, round tube) and extension unit",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP2200 Comfort Pro for support arm (not extendable, flange on top)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP2200 Comfort Pro neutral design for stand (expandable, flange at the bottom)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (expandable, round tube) and extensio",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP2200 Comfort Pro neutral design for support arm (not extendable, flange on top)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP2200 Unified Comfort Hygienic",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP2200 Unified Comfort Hygienic neutral design",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP2200 Unified Comfort Panel",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP2200 Unified Comfort Panel neutral design",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP700\u00a0Unified Comfort Panel",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP700 Unified Comfort Panel hygienic neutral design",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC HMI MTP700, Unified Comfort Panel neutral design",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IOT2050",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.25.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC BX-39A Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC BX-59A Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC127E Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC227E Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC227G Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC427E Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC847E Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIPLUS HMI MTP1000 Unified Comfort",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIPLUS HMI MTP1200 Unified Comfort",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIPLUS HMI MTP700 Unified Comfort",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V21",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 10,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          }
        },
        {
          "cvssV4_0": {
            "baseScore": 10,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-639",
              "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-01-13T09:44:03.338Z",
        "orgId": "cec7a2ec-15b4-4faf-bd53-b40f371f3a77",
        "shortName": "siemens"
      },
      "references": [
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-014678.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-001536.html"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "cec7a2ec-15b4-4faf-bd53-b40f371f3a77",
    "assignerShortName": "siemens",
    "cveId": "CVE-2025-40805",
    "datePublished": "2026-01-13T09:44:03.338Z",
    "dateReserved": "2025-04-16T08:50:26.973Z",
    "dateUpdated": "2026-01-13T17:37:40.414Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2024-54092 (GCVE-0-2024-54092)
Vulnerability from cvelistv5
Published
2025-04-08 08:22
Modified
2025-07-08 10:34
CWE
Summary
A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (All versions), Industrial Edge Device Kit - arm64 V1.19 (All versions), Industrial Edge Device Kit - arm64 V1.20 (All versions < V1.20.2-1), Industrial Edge Device Kit - arm64 V1.21 (All versions < V1.21.1-1), Industrial Edge Device Kit - x86-64 V1.17 (All versions), Industrial Edge Device Kit - x86-64 V1.18 (All versions), Industrial Edge Device Kit - x86-64 V1.19 (All versions), Industrial Edge Device Kit - x86-64 V1.20 (All versions < V1.20.2-1), Industrial Edge Device Kit - x86-64 V1.21 (All versions < V1.21.1-1), Industrial Edge Own Device (IEOD) (All versions < V1.21.1-1-a), Industrial Edge Virtual Device (All versions < V1.21.1-1-a), SCALANCE LPE9413 (6GK5998-3GS01-2AC2) (All versions < V2.1), SIMATIC IPC BX-39A Industrial Edge Device (All versions < V3.0), SIMATIC IPC BX-59A Industrial Edge Device (All versions < V3.0), SIMATIC IPC127E Industrial Edge Device (All versions < V3.0), SIMATIC IPC227E Industrial Edge Device (All versions < V3.0), SIMATIC IPC427E Industrial Edge Device (All versions < V3.0), SIMATIC IPC847E Industrial Edge Device (All versions < V3.0). Affected devices do not properly enforce user authentication on specific API endpoints when identity federation is used. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that identity federation is currently or has previously been used and the attacker has learned the identity of a legitimate user.
Impacted products
Vendor Product Version
Siemens Industrial Edge Device Kit - arm64 V1.17 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.18 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.19 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.20 Version: 0   < V1.20.2-1
Create a notification for this product.
   Siemens Industrial Edge Device Kit - arm64 V1.21 Version: 0   < V1.21.1-1
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.17 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.18 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.19 Version: 0   < *
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.20 Version: 0   < V1.20.2-1
Create a notification for this product.
   Siemens Industrial Edge Device Kit - x86-64 V1.21 Version: 0   < V1.21.1-1
Create a notification for this product.
   Siemens Industrial Edge Own Device (IEOD) Version: 0   < V1.21.1-1-a
Create a notification for this product.
   Siemens Industrial Edge Virtual Device Version: 0   < V1.21.1-1-a
Create a notification for this product.
   Siemens SCALANCE LPE9413 Version: 0   < V2.1
Create a notification for this product.
   Siemens SIMATIC IPC BX-39A Industrial Edge Device Version: 0   < V3.0
Create a notification for this product.
   Siemens SIMATIC IPC BX-59A Industrial Edge Device Version: 0   < V3.0
Create a notification for this product.
   Siemens SIMATIC IPC127E Industrial Edge Device Version: 0   < V3.0
Create a notification for this product.
   Siemens SIMATIC IPC227E Industrial Edge Device Version: 0   < V3.0
Create a notification for this product.
   Siemens SIMATIC IPC427E Industrial Edge Device Version: 0   < V3.0
Create a notification for this product.
   Siemens SIMATIC IPC847E Industrial Edge Device Version: 0   < V3.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-54092",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-04-08T13:27:19.071254Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-04-08T13:27:35.300Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.17",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.18",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.19",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.20",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.20.2-1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - arm64 V1.21",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.21.1-1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.17",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.18",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.19",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "*",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.20",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.20.2-1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Device Kit - x86-64 V1.21",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.21.1-1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Own Device (IEOD)",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.21.1-1-a",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "Industrial Edge Virtual Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V1.21.1-1-a",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SCALANCE LPE9413",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V2.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC BX-39A Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC BX-59A Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC127E Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC227E Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC427E Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "SIMATIC IPC847E Industrial Edge Device",
          "vendor": "Siemens",
          "versions": [
            {
              "lessThan": "V3.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (All versions), Industrial Edge Device Kit - arm64 V1.19 (All versions), Industrial Edge Device Kit - arm64 V1.20 (All versions \u003c V1.20.2-1), Industrial Edge Device Kit - arm64 V1.21 (All versions \u003c V1.21.1-1), Industrial Edge Device Kit - x86-64 V1.17 (All versions), Industrial Edge Device Kit - x86-64 V1.18 (All versions), Industrial Edge Device Kit - x86-64 V1.19 (All versions), Industrial Edge Device Kit - x86-64 V1.20 (All versions \u003c V1.20.2-1), Industrial Edge Device Kit - x86-64 V1.21 (All versions \u003c V1.21.1-1), Industrial Edge Own Device (IEOD) (All versions \u003c V1.21.1-1-a), Industrial Edge Virtual Device (All versions \u003c V1.21.1-1-a), SCALANCE LPE9413 (6GK5998-3GS01-2AC2) (All versions \u003c V2.1), SIMATIC IPC BX-39A Industrial Edge Device (All versions \u003c V3.0), SIMATIC IPC BX-59A Industrial Edge Device (All versions \u003c V3.0), SIMATIC IPC127E Industrial Edge Device (All versions \u003c V3.0), SIMATIC IPC227E Industrial Edge Device (All versions \u003c V3.0), SIMATIC IPC427E Industrial Edge Device (All versions \u003c V3.0), SIMATIC IPC847E Industrial Edge Device (All versions \u003c V3.0). Affected devices do not properly enforce user authentication on specific API endpoints when identity federation is used. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that identity federation is currently or has previously been used and the attacker has learned the identity of a legitimate user."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          }
        },
        {
          "cvssV4_0": {
            "baseScore": 9.3,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-1390",
              "description": "CWE-1390: Weak Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-07-08T10:34:27.627Z",
        "orgId": "cec7a2ec-15b4-4faf-bd53-b40f371f3a77",
        "shortName": "siemens"
      },
      "references": [
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-634640.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-819629.html"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "cec7a2ec-15b4-4faf-bd53-b40f371f3a77",
    "assignerShortName": "siemens",
    "cveId": "CVE-2024-54092",
    "datePublished": "2025-04-08T08:22:24.861Z",
    "dateReserved": "2024-11-28T13:06:14.569Z",
    "dateUpdated": "2025-07-08T10:34:27.627Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}